PoCs and tools for investigation of Windows process execution techniques
Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".
A lightweight native DLL mapping library that supports mapping directly from memory
翻译 - 轻量级的本机DLL映射库,支持直接从内存进行映射
Intercept Windows Named Pipes communication using Burp or similar HTTP proxy tools